New Linux kernel SMB security flaw revealed (2024)

New Linux kernel SMB security flaw revealed (1)

Tux

Ksmbd, introduced to the kernel in 2021, was developed by Samsung. Its goal was to deliver speedy SMB3 file-serving performance. SMB is used in Windows and Linux--via Samba--as an important file server protocol. Most distributions do not have Ksmbd compiled into the kernel or enabled by default.

But, if you have it in your kernel and enabled, pay attention. CVE-2023-0210 is a hole in the program's New Technology LAN Manager (NTLM) authentication. A knowledgeable attacker, with remote access to the server and a valid user name, could abuse it to overflow the allocated heap buffer.

This overflow, according to Sysdig, is too large to be used for remote code exploitation. That's the good news. The bad news is it can still cause a kernel panic, which would cause a denial of service.

Who wants a crashed server? I don't.

Still, Red Hat gives CVE-2023-0210 a Common Vulnerability Scoring System (CVSS) rating of 5.9, which is important, but far from critical. No Red Hat Enterprise Linux (RHEL) version, by the by, has this bug.

It gets such a comparatively low rating because to exploit, you must have KSMBD enabled. Since it's deployed in a module, you must enable and configure Ksmbd yourself. That's not a trivial job. Besides, only a security idiot exposes SMB port, 455, to the Internet, since, with its access to file systems, it's just asking to be attacked.

If you are using it, upgrade to the newly released Linux Kernel 6.2 RC4 or higher.

It's important to note that this problem has nothing to do with Samba, which is commonly used on Linux desktops and file servers. As Jeremy Allison, Samba's co-creator, told me about the earlier, more serious, hole, "ksmbd shares no code with production Samba. It's completely from scratch. So, this current situation has nothing to do with the Samba file server you may be running on your systems." The same is true of this vulnerability.

Personally, I'd steer clear of ksmbd for now. It may be faster than Samba, but two security problems in a row are two too many. And, besides, Samba's been battle-tested for over 30 years. I know which one I'm trusting on my production servers.

Other noteworthy Linux and open-source stories:

New Linux kernel SMB security flaw revealed (2024)
Top Articles
What is the Tax Cuts and Jobs Act (TCJA)?
You want to be a successful writer. What are the most effective ways to market yourself?
Aberration Surface Entrances
Spn 1816 Fmi 9
Week 2 Defense (DEF) Streamers, Starters & Rankings: 2024 Fantasy Tiers, Rankings
Best Big Jumpshot 2K23
Blairsville Online Yard Sale
Unraveling The Mystery: Does Breckie Hill Have A Boyfriend?
Tribune Seymour
Mikayla Campino Video Twitter: Unveiling the Viral Sensation and Its Impact on Social Media
Uc Santa Cruz Events
Was sind ACH-Routingnummern? | Stripe
Osrs Blessed Axe
Santa Clara Valley Medical Center Medical Records
Mycarolinas Login
Dusk
The Murdoch succession drama kicks off this week. Here's everything you need to know
How do you like playing as an antagonist? - Goonstation Forums
Craigslist Farm And Garden Cincinnati Ohio
Craigslist Malone New York
Morgan And Nay Funeral Home Obituaries
Unit 33 Quiz Listening Comprehension
Theresa Alone Gofundme
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
Paychex Pricing And Fees (2024 Guide)
Csi Tv Series Wiki
Officialmilarosee
UPS Store #5038, The
Program Logistics and Property Manager - Baghdad, Iraq
Iu Spring Break 2024
Poe Str Stacking
Hampton University Ministers Conference Registration
Elite Dangerous How To Scan Nav Beacon
Urbfsdreamgirl
Buhl Park Summer Concert Series 2023 Schedule
Mami No 1 Ott
Turns As A Jetliner Crossword Clue
CohhCarnage - Twitch Streamer Profile & Bio - TopTwitchStreamers
Tu Housing Portal
Account Now Login In
Napa Autocare Locator
Craigslist Car For Sale By Owner
Eleceed Mangaowl
State Legislatures Icivics Answer Key
Wattengel Funeral Home Meadow Drive
Sig Mlok Bayonet Mount
Hanco*ck County Ms Busted Newspaper
15:30 Est
Craigslist Pets Lewiston Idaho
BYU Football: Instant Observations From Blowout Win At Wyoming
Costco Gas Price Fort Lauderdale
Asisn Massage Near Me
Latest Posts
Article information

Author: Zonia Mosciski DO

Last Updated:

Views: 5926

Rating: 4 / 5 (51 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Zonia Mosciski DO

Birthday: 1996-05-16

Address: Suite 228 919 Deana Ford, Lake Meridithberg, NE 60017-4257

Phone: +2613987384138

Job: Chief Retail Officer

Hobby: Tai chi, Dowsing, Poi, Letterboxing, Watching movies, Video gaming, Singing

Introduction: My name is Zonia Mosciski DO, I am a enchanting, joyous, lovely, successful, hilarious, tender, outstanding person who loves writing and wants to share my knowledge and understanding with you.